CVE-2006-4768
Estado: ModificadaMedia (5)—
Multiple direct static code injection vulnerabilities in add_go.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via the (1) description, (2) issue, (3) title, (4) var, (5) name, (6) keywords, and (7) note parameters, which are stored in an article file. NOTE: the original source of this vulnerability is unknown; the details are obtained from third party information and CVE post-disclosure analysis.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.33%
- Percentil entre todas las CVEs puntuadas: 70
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/21826
- http://www.osvdb.org/28814
- http://www.securityfocus.com/bid/84155
- http://www.vupen.com/english/advisories/2006/3558
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28900
- http://secunia.com/advisories/21826
- http://www.osvdb.org/28814
- http://www.securityfocus.com/bid/84155
- http://www.vupen.com/english/advisories/2006/3558
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28900
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-4768",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-09-13T23:07:00.000",
"references": [
{
"url": "http://secunia.com/advisories/21826",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/28814",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/84155",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3558",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28900",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21826",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/28814",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/84155",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3558",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28900",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple direct static code injection vulnerabilities in add_go.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via the (1) description, (2) issue, (3) title, (4) var, (5) name, (6) keywords, and (7) note parameters, which are stored in an article file. NOTE: the original source of this vulnerability is unknown; the details are obtained from third party information and CVE post-disclosure analysis."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de inyección estática directa de código en add_go.php en Stefan Ernst Newsscript (también conocido como WM-News) 0.5 beta permite a un atacante remoto ejecutar código PHP de su elección a través de los parámetros (1) description, (2) issue, (3) title, (4) var, (5) name, (6) keywords, y (7) note, lo cuales se alamacenan en un fichero de artículo. NOTA: la fuente original de esta vulnerabilidad es desconocida; los detalles se obtuverion a partir de información de terceros y del análisis de revelaciones posteriores del CVE."
}
],
"lastModified": "2026-06-16T22:29:45.600",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:stefan_ernst:newsscript:0.5_beta:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4D67AD5-932A-4C93-A632-918C49232F2D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}